In the Claims: 

Please amend claims 5, 10, 19 and 25. The claims are as follows: 
1-4. (Canceled) 

5. (Currently amended) A method of operating an intrusion detection system^ comprising the 
steps of: 

monitoring, by the intrusion detection system, for occurrence of a signature event that is 
indicative of a denial of service intrusion on a protected device, said denial of service attack 
intrusion attempting to impede operation of the protected device; and 

when a signature event occurs, increasing a value of a signature event counter and 
comparing the value of the signature event counter with a signature threshold quantity; and 

when the value of the signature event counter exceeds the signature threshold quantity, 
generating an alert by an intrusion detection sensor of the intrusion detection system, recording a 
time of generating the alert in a log of a govemor comprised by the intrusion detection sensor, 
determining from contents of the log a present alert generation rate, and comparing the present 
alert generation rate with an alert generation rate threshold; and 

when the present alert generation rate exceeds the alert generation rate threshold, altering 
an element of a signature set of the intrusion detection system to decrease an alert generation rate 
of the intrusion detection sensor. 
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6. (Previously presented) The method of claim 5, wherein the element is the signature threshold 
quantity. 

7. (Previously presented) The method of claim 5, wherein the element is a signature threshold 
interval that specifies a sliding time window. 

8-9. (Canceled) 

10. (Currently amended) Progranmiable media containing programmable software for operation 
of an intrusion detection system, programmable software comprising the steps of: 

monitoring, by the intrusion detection system, for occurrence of a signature event that is 
indicative of a denial of service intrusion on a protected device, said denial of service attack 
intrusion attempting to impede operation of the protected device; and 

when a signature event occurs, increasing a value of a signature event counter and 
comparing the value of the signature event counter with a signature threshold quantity; and 

when the value of the signature event counter exceeds the signature threshold quantity, 
generating an alert by an intrusion detection sensor of the intrusion detection system, recording a 
time of generating the alert in a log of a governor comprised by the intrusion detection sensor, 
determining fi-om contents of the log a present alert generation rate, and comparing the present 
alert generation rate with an alert generation rate threshold; and 
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when the present alert generation rate exceeds the alert generation rate threshold, altering 
an element of a signature set of the intrusion detection system to decrease an alert generation rate 
of the intrusion detection server. 

1 1 . (Previously presented) The programmable media of claim 10, wherein the element is the 
signature threshold quantity, 

12. (Previously presented) The programmable media of claim 10, wherein the element is a 
signataire threshold interval that specifies a sliding time window. 

13-18. (Canceled) 

19. (Currently amended) The method of claim 5, wherein said generating the alert comprises 
alerting an administrator of suspected denial of service intrusions upon the prot e ct protected 
device. 

20. (Previously presented) The method of claim 5, wherein the alert generation rate threshold is 
comprised by the governor. 

21 . (Previously presented) The method of claim 5, wherein the signature set comprises a unique 
signature set identifier, the signature event, the signature event counter, the signature threshold 
quantity, and a signature threshold interval that specifies a sliding time window. 
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22. (Previously presented) The method of claim 5, wherein the protected device is selected from 
the group consisting of a computer, a web server, and a workstation. 

23. (Previously presented) The method of claim 5, wherein the method farther comprises the step 

ptitprina infn thp Ina ^ lict n'P timpictamnG that rf^rnrA thf^ timp« at whirh thp intmcinn Hptpptinn 

sensor generates alerts, wherein said determining from contents of the log a present alert 
generation rate utilizes the timestamps in the log. 

24. (Previously presented) The method of claim 5, wherein after generating the alert and before 
determining from contents of the log the present alert generation rate, the method further 
comprises the step of: 

clearing the log of any entries that are past a specified age. 

25. (Currently amended) The programmable media of claim 10, wherein said generating the alert 
comprises alerting an administrator of suspected denial of service intrusions upon the protect 
protected device. 

26. (Previously presented) The programmable media of claim 10, wherein the alert generation 
rate threshold is comprised by the govemor. 
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27. (Previously presented) The programmable media of claim 10, wherein the signature set 
comprises a unique signature set identifier, the signature event, the signature event counter, the 
signature threshold quantity, and a signature threshold interval that specifies a sliding time 
window. 

28. (Previously presented) The programmable media of claim 10, wherein the protected device is 
selected from the group consisting of a computer, a web server, and a workstation. 

29. (Previously presented) The programmable media of claim 10, wherein the programmable 
software further comprises the step of entering into the log a list of timestamps that record the 
times at which the intrusion detection sensor generates alerts, wherein said determining from 
contents of the log a present alert generation rate utilizes the timestamps in the log. 

30. (Previously presented) The programmable media of claim 10, wherein after generating the 
alert and before determining from contents of the log the present alert generation rate, the 
programmable software further comprises the step of: 

clearing the log of any entries that are past a specified age. 
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